arXiv:2506.04823cs.CVcs.LG2025-06中稿 · publication at IV …被引 4

用打印贴纸欺骗交通灯检测模型,实现真实场景下的攻击

Fool the Stoplight: Realistic Adversarial Patch Attacks on Traffic Light Detectors

  • 在交通灯下方贴打印贴纸,诱导模型误判
  • 实测可实现红转绿的标签翻转,且在真实场景中有效
  • 适用于自动驾驶安全测试与防御研究

针对自动驾驶车辆基于摄像头的感知任务,已有研究成功演示了多种现实场景下的对抗攻击。然而,针对交通灯检测器的攻击仍较少。本文展示了如何利用打印贴纸对交通灯检测的CNN模型实施对抗攻击。提出一种威胁模型:每个交通灯实例均在其下方放置一个贴纸,并设计相应的训练策略。实验表明,在通用场景下可实现成功的对抗贴纸攻击,包括目标导向的红转绿标签翻转以及图案分类攻击。最后,在实验室环境中使用移动式施工交通灯和固定交通灯进行了真实世界评估,验证了攻击的有效性。代码已公开于 https://github.com/KASTEL-MobilityLab/attacks-on-traffic-light-detection。

原文摘要 · Abstract (English)

Realistic adversarial attacks on various camera-based perception tasks of autonomous vehicles have been successfully demonstrated so far. However, only a few works considered attacks on traffic light detectors. This work shows how CNNs for traffic light detection can be attacked with printed patches. We propose a threat model, where each instance of a traffic light is attacked with a patch placed under it, and describe a training strategy. We demonstrate successful adversarial patch attacks in universal settings. Our experiments show realistic targeted red-to-green label-flipping attacks and attacks on pictogram classification. Finally, we perform a real-world evaluation with printed patches and demonstrate attacks in the lab settings with a mobile traffic light for construction sites and in a test area with stationary traffic lights. Our code is available at https://github.com/KASTEL-MobilityLab/attacks-on-traffic-light-detection.

对抗攻击交通灯检测自动驾驶安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。